sickkids.ca Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The sickkids.ca Listed by lockbit3 Ransomware Group (reported December 31, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 31 December 2022, the website sickkids.ca appeared on a leak site operated by the ransomware group known as lockbit3. Public reporting at the time indicated that internal files had been exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical detail about the intrusion has not been disclosed in the available record.
The listing itself is a claim by the group. In a statement attributed to lockbit3, the group said it formally apologized for the attack, provided a decryptor free of charge, and asserted that the affiliate who carried out the incident had violated its rules, been blocked, and removed from its affiliate program. For patients, families, and staff connected to a major children’s hospital, any confirmed or claimed exposure of internal material raises immediate questions about what was taken and what practical steps follow.
What happened
According to the reported facts, sickkids.ca was listed by lockbit3 on 31 December 2022. The record states that internal files were exfiltrated in a ransomware attack. No public figure has been given for the number of individuals affected, and the available summary does not describe the initial access method, the duration of unauthorized access, or a full inventory of systems involved.
lockbit3’s own statement, as reported, framed the incident as a violation of the group’s rules by a partner or affiliate. The group claimed it was releasing the decryptor at no cost and ending that affiliate’s participation. Beyond that claim and the confirmation that internal files were taken, timing of the underlying intrusion, the precise scale of encryption or theft, and any independent verification of the group’s assertions remain undisclosed in the material provided.
Inside lockbit3
lockbit3 is the name associated with a long-running ransomware operation that has functioned on a ransomware-as-a-service model. In that model, core operators maintain the malware and leak infrastructure while affiliates conduct intrusions and share proceeds. Groups of this type commonly gain access through stolen credentials, exploited vulnerabilities, or phishing, then move laterally, exfiltrate data, and deploy encryption before posting victims on a dedicated leak site to increase pressure.
Public reporting over several years has documented lockbit-branded operations against organizations across healthcare, manufacturing, government, and professional services in multiple countries. The group has frequently used double-extortion tactics: threatening both to withhold decryption keys and to publish stolen data. In this specific case, the only statements attributed to lockbit3 about sickkids.ca are the apology, the free release of a decryptor, and the claim that the responsible affiliate was expelled for breaking internal rules. No additional claims by the group about the contents of the stolen files are included in the facts at hand, and the leak-site listing should be treated as an unverified claim unless independently confirmed.
About sickkids.ca
sickkids.ca is the online presence of The Hospital for Sick Children (SickKids) in Toronto, one of Canada’s principal paediatric academic health-science centres. Institutions of this kind deliver specialized clinical care to children and adolescents, conduct research, train medical professionals, and manage extensive administrative and operational systems. They routinely handle highly sensitive information, including clinical records, diagnostic data, family contact details, research datasets, staff records, and internal operational documents.
A ransomware incident affecting a children’s hospital is consequential because the organization sits at the intersection of acute care, long-term patient relationships, and research. Disruption can affect scheduling, diagnostics, and continuity of care; any exposure of internal files raises privacy and safety concerns for minors and their families that differ in degree from many other sectors. The facts do not establish negligence or specific security failures; they establish only that the organization was listed and that internal files were reported as exfiltrated.
What was likely exposed
The facts name the exposed material as “internal files exfiltrated in a ransomware attack.” No further breakdown—such as patient charts, billing records, employee data, research files, or email archives—is provided. The number of people affected is listed as unknown.
Organizations of this type typically hold clinical documentation, laboratory and imaging results, demographic and contact information for patients and guardians, insurance and billing data, human-resources files, and internal correspondence. It is reasonable to expect that some mixture of operational and potentially personal information could have been among internal files, yet the exact contents remain unconfirmed. Readers should not treat any specific category as established fact for this incident.
The real-world impact
For individuals, the primary risks associated with exfiltrated internal hospital files include possible misuse of personal or clinical information, targeted phishing that references real details, and, in rarer cases, identity-related fraud. Because the affected population may include children, guardians often bear the practical burden of monitoring accounts and communications. Without a confirmed inventory or headcount, it is not possible to state how many people face elevated risk or which data elements are involved.
For the organization, consequences can include operational disruption during containment and recovery, regulatory notification duties, reputational strain, and the cost of investigation and remediation. The group’s claim that a decryptor was released freely may have reduced some encryption-related downtime, but it does not eliminate concerns about data that had already left the environment. Independent confirmation of what was taken and whether any data was later published is not contained in the available facts.
Were you affected?
If you are a patient, family member, or staff member connected to SickKids, treat the incident as a prompt to increase vigilance rather than as proof that your own information was included. Monitor financial and email accounts for unexpected messages that appear to reference hospital care. Prefer official channels for any communication about the incident, and be cautious with unsolicited links or attachments. Consider placing fraud alerts or credit freezes where appropriate under local law, especially if you later receive formal notice that your data was involved.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step does not confirm or rule out involvement in this specific incident, but it can surface credentials or personal details that have circulated elsewhere and deserve attention. Official updates, if any, should come from the hospital or relevant regulators; until more detail is published, the prudent course is measured monitoring rather than assumption of either safety or confirmed compromise.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
chs.ca Listed by lockbit3 Ransomware Groupnosm.ca Listed by dispossessor Ransomware Grouparistopharma.com Listed by lockbit3 Ransomware Groupmayflowerdentalgroup.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the sickkids.ca Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.